Public Architecture Map
Exawatt Architecture
Exawatt is a command interface for managing agent fleets across local, customer-hosted, and third-party harnesses.
Reviewed 2026-09-07
System
System Boundary
Exawatt sits between people directing work and the agent sources that execute it.
Agent Infrastructure Layer
Agent sources, gateways, harnesses, credentials, local runtimes, and hosted control planes.
Dynamic Range
Microscope
Inspect one Agent, its current contexts, tool history, blockers, diffs, and approvals.
Mission Control
See fleet allocation, initiatives, outcomes, risk, policy, and consumption.
Architecture Rules
UI surfaces speak Exawatt nouns, not provider-specific vocabulary.
DOM and Fleet Operations Board regimes share typed view models and command contracts.
Agent, Team, and Fleet form one navigation continuum while keeping separate renderer boundaries.
React owns discrete semantic state; Chromium compositing, the xterm renderer, and R3F own continuous pixels. Performance changes begin with an attributed gesture trace, preserve existing failure paths, and change the narrowest proven owner.
Appearance is app-global and source-neutral: one validated snapshot feeds DOM, xterm, R3F, and Electron adapters while product-state color channels keep their meanings.
Project identity is opaque, durable, renameable, and folder-optional across Agent, Team, and Fleet; Agents join by Project id, and folder-dependent actions remain absent until a local folder is bound.
The Agent altitude projects current Session tabs as Initiative-shaped work: selected Projects expand, manual inactive disclosure persists, dormant empties stable-partition to the tail, and subagent work aggregates instead of multiplying top-level tabs.
Session identity remains durable across Agent, Team, and Fleet but stays subordinate to the coworker-shaped Agent; PTYs add live runtime state without defining Agent existence.
The primary roster projects source-native topology into coworker-shaped Agents: configured OpenClaw Agents remain one coworker above many contexts, while raw source identities stay preserved and re-projectable.
An Agent opens at its source-declared primary conversation rather than the latest activity; background contexts form a subordinate work stack and concurrency alone never creates a coworker.
Placement is orthogonal to Agent identity: local, customer-hosted, and Exawatt-hosted configured sources use the same Agent, Project, state, and command contracts.
Connection freshness is not work state: closing Exawatt or losing a remote observation path never implies that a remote Agent stopped; reconnect resnapshots authoritative state because transport sequence may be connection-local.
Pause is a resumable-continuity capability, not disconnect: a remote adapter must verify both the halted scope and preservation of the same source-native work before Exawatt offers generic Pause and Resume verbs.
Logical Sessions survive local process death through explicit, deterministic rehydration; recovery defaults to the selected Project with Agent and all-Projects as nested alternate scopes, and local processes do not outlive Exawatt.
Agent turn state is semantic main-process truth: finished is sticky across passive PTY redraws and only explicit operator engagement opens the next turn; shell activity remains output-driven.
What a harness reports about itself outranks what Exawatt infers from its bytes, in both directions and at the source: quiescence never concludes a turn ended, delegated, or unblocked while the source says otherwise.
Delegation is source-declared evidence: Codex parent/child lifecycle comes only from its version-probed app-server protocol, reconnect resnapshots exact thread IDs, and an unavailable or incompatible protocol withdraws to absent without filesystem, process, worktree, or terminal inference.
Waiting on the operator is its own reported fact, independent of turn state and of delegation: an Agent asking a question is mid-turn, producing nothing, and answerable only by a human.
Independent attention sources compose semantically and declare their scope: human gates outrank quiet results, merged coverage is the intersection of the sources, and only a map every source covers may drive fleet-wide markers, availability, and navigation — a producer with a narrower lens answers unknown, never quiet.
Attention records what the operator has not yet seen; the status light records what is currently true. Focusing a Session changes the first and never the second.
Session context labels follow submitted operator intent, never PTY output volume; one hosted inference path improves a durable last-good label while failures retain it.
Goal visuals are quiet projections of accepted Session context: semantic pivots own revision cadence, a private identity derives the provider-facing natural scene without transmitting goal text, Demo/Live share deterministic fallback behavior, and one app-global device preference gates Electron and hosted renderers.
Product feedback is explicit authenticated evidence with row ownership and private attachments; inference evidence is not persisted as feedback automatically.
Public operator statistics are an opt-in aggregate projection over the shared local Consumption spine: Electron settings preserve the consent boundary across renderer origins, uploads are allowlisted, and disabling public visibility leaves local history untouched.
Session-continuity diagnostics are local, explainable projections over evidence; hosted systems may aggregate them but never replace their semantics with an opaque health score.
Agent sources are replaceable harnesses behind explicit adapters.
Public-source publication preserves its published prefix, classifies later commits independently, and requires exact-candidate certification for an explicit snapshot recovery; ordinary publication never rewrites public history.
Distribution services are optional versioned capabilities resolved before build; community identity is isolated and service-neutral, while operator-configured Agent Source WebSockets remain an independent local/customer-owned transport.
Distribution artwork crosses process creation as a validated file reference and digest; binary asset bytes never ride in child environment values.
Coding is the first dogfood workload, not the Agent boundary; compatible non-coding sources use the same command and evidence contracts.
Source entitlement and Consumption are separate: a compatible subscription-backed harness does not require Exawatt API billing, and unreported plan headroom stays unknown.
A Launch Configuration is one exact configured source/model/effort choice; only successful launches train per-Project frecency, Project pins stay local, and unavailable choices never silently substitute.
Shell is a distinct peer launch target with no Agent identity or composer task; Clone creates a fresh Agent Session with bounded handoff text, preserves the original, and carries no provider resume identity.
Recent conversation discovery is Project-scoped, local-first, and source-neutral; exact identity reconciles Exawatt Session history with harness history before optional hosted title augmentation.
Launch permission policy is source-agnostic and provider-enforced today; adapters translate visible personal Project defaults without silent escalation.
Activity assurance is composable: reported, observed, authorized, enforced, and verified are independent claims, and unknowns stay visible.
Future managed Workspace ceilings cannot be bypassed by personal settings or YOLO; later mediation fits behind existing source and coordination contracts.
Demo behavior is a swappable harness path, not a separate product architecture.
Governance, memory, and resource context live above individual providers.